Unrated severityNVD Advisory· Published Mar 18, 2026· Updated Mar 19, 2026
NULL pointer dereference in samtools cram-size
CVE-2026-31973
Description
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in the cram-size command, used to write information about how well CRAM files are compressed, a check to see if the cram_decode_compression_header() was missing. If the function returned an error, this could lead to a NULL pointer dereference. Exploiting this bug causes a NULL pointer dereference. Typically this will cause the program to crash. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. There is no workaround for this issue.
Affected products
2- samtools/samtoolsv5Range: >= 1.17, < 1.21.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/samtools/samtools/commit/06fc2a219b3d7c94d3f412c09f6d1efd51199f2fmitrex_refsource_MISC
- github.com/samtools/samtools/security/advisories/GHSA-x86f-q6fj-cm43mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.